LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-40622

nlnetlabs · unbound

Published
CVSS7.5
Severityhigh
WeaknessCWE-346
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query

References

← Back to the CVE Tracker

Our coverage of CVE-2026-40622

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-40622.